Webserver
by Roxen
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0671 | 0.04 | — | 0.08 | Jul 21, 2000 | Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL. | |||
| CVE-1999-0235 | 0.04 | — | 0.07 | Feb 17, 1995 | Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. | |||
| CVE-2003-1318 | 0.03 | — | 0.03 | Dec 31, 2003 | Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376. | |||
| CVE-2001-1118 | 0.00 | — | 0.03 | Aug 2, 2001 | A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL. | |||
| CVE-1999-1522 | 0.00 | — | 0.01 | Oct 7, 1999 | Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML. | |||
| CVE-1999-1125 | 0.00 | — | 0.04 | Sep 19, 1997 | Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. |
- CVE-2000-0671Jul 21, 2000risk 0.04cvss —epss 0.08
Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.
- CVE-1999-0235Feb 17, 1995risk 0.04cvss —epss 0.07
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
- CVE-2003-1318Dec 31, 2003risk 0.03cvss —epss 0.03
Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.
- CVE-2001-1118Aug 2, 2001risk 0.00cvss —epss 0.03
A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.
- CVE-1999-1522Oct 7, 1999risk 0.00cvss —epss 0.01
Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.
- CVE-1999-1125Sep 19, 1997risk 0.00cvss —epss 0.04
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.